Goal
Keep this pnpm monorepo and its GitHub Actions dependencies up to date automatically, while validating changes before they are merged.
Scope
- Configure Dependabot version updates for the repository's pnpm workspace manifests and lockfiles, including the separately locked
packages/uilib package.
- Check for updates weekly, apply an explicit 3-day cooldown after a dependency release, and group compatible updates to keep pull-request volume manageable.
- Configure weekly updates for GitHub Actions with the same 3-day version-update cooldown.
- Enable the dependency graph, Dependabot alerts, and Dependabot security updates so known vulnerabilities are reported and secure-version pull requests are created. These repository security settings require a repository administrator; they cannot be enabled by
dependabot.yml alone.
- Ensure Dependabot pull requests run the repository's applicable build, test, and lint checks.
Merge policy
Dependabot should automatically open update pull requests; this does not mean those pull requests should be merged automatically. Keep auto-merge disabled initially. Consider enabling it later only for agreed low-risk updates after required checks and branch protection are verified; major updates should remain subject to review.
The 3-day cooldown applies to version updates only. Security update pull requests are not delayed by this cooldown.
Acceptance criteria
- Dependabot configuration covers pnpm dependencies across the monorepo and GitHub Actions.
- Version updates observe a 3-day cooldown; security updates remain unaffected.
- A repository administrator enables the dependency graph, Dependabot alerts, and security update pull requests.
- Dependabot pull requests receive the applicable CI checks.
- The first generated updates are reviewed and the setup is verified; no update is auto-merged by default.
Goal
Keep this pnpm monorepo and its GitHub Actions dependencies up to date automatically, while validating changes before they are merged.
Scope
packages/uilibpackage.dependabot.ymlalone.Merge policy
Dependabot should automatically open update pull requests; this does not mean those pull requests should be merged automatically. Keep auto-merge disabled initially. Consider enabling it later only for agreed low-risk updates after required checks and branch protection are verified; major updates should remain subject to review.
The 3-day cooldown applies to version updates only. Security update pull requests are not delayed by this cooldown.
Acceptance criteria